FortiOS sslvpnd CVE-2022-42475 Exploitation Indicator Keyword Matching

Flags FortiOS sslvpnd activity containing known CVE-2022-42475 artifact paths from file-related events.

FreeReviewedSigma · High · v5
Product
fortios
Service
sslvpnd
Author
Nasreddine Bencherchali (Nextron Systems), Nilaa Maharjan, Douglasrose75 (SigmaHQ), DRL 1.1
Published
2024-02-08
Updated
2026-07-31

What it detects

This rule flags exploitation indicators for CVE-2022-42475 by matching specific file path and configuration artifact keywords observed in the sslvpnd context on FortiOS. Attackers exploiting this heap-based buffer overflow may leave behind these file or backup-related indicators, making their appearance a useful signal for compromise attempts. The detection relies on FortiOS sslvpnd telemetry that captures file creation events (or equivalent) and surfaces the referenced paths in collected logs.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.